Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
Security /

Firm warns of NetWare security hole

Today's breaking news
Send to a friendFeedback

Advertisement:


IT managers of NetWare 5.1 and NetWare 6 networks need to be aware of a vulnerability in the operating system that makes it subject to intrusions that could cause the system to crash.

IXSecurity.com, an IT security firm, Thursday reported that NetWare 5.1 and 6 are vulnerable to a buffer overflow condition that could affect server operation.

Both operating systems can be attacked through the NetWare 6 Remote Manager utility, also called the Portal NLM (NetWare Loadable Module), a Web-based server management interface. With scripts or just the correct combination of keystrokes, intruders could cause servers to crash or abend (Abnormal End), or they could execute code on the server.

IXSecurity claims it notified Novell last month about the problem and Novell failed to respond. IXSecurity suggests that users disable the NetWare Remote Manager NLM called HTTPSTK.NLM until Novell issues a patch.

The vulnerability, Novell indicates occurs when an intruder launches a script against the authentication for the site. The company claims that normal browser access doesn't allow this kind of denial-of-service attack.

Nonetheless, without the fix there are existing ways to restrict access to the NetWare Remote Manager, such as by applying IP filtering to secure port 8009 or using some of the utilities built into the utility itself.

Novell indicates it will have a patch for this vulnerability as soon as Monday. The patch, which the company says should be applied to all NetWare 5.1 and 6 servers, can be downloaded from the technical patch site. The patch, which consists of a new version of HTTPSTK.NLM, will also be added into the next Novell support pack.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.